05-18-2019 12:16 PM
Hi,
I have planning to implement secondary asa 5585 in HA so what I have configure in secondary device ???
05-18-2019 03:30 PM
here is good document to start with :
https://www.thegeekstuff.com/2011/09/cisco-asa-high-availability/
05-18-2019 07:31 PM
Hi ,
I have read the article but in my senario my primary is failed and secondary become active so I have to replaced new one in current live setup without affecting the secondary-active configuration.so what is the best way to complete this task.
05-18-2019 08:47 PM - edited 05-18-2019 08:48 PM
This has been answered several times over the years. ASA HA configuration has not changed significantly since, so the earlier threads remain valid:
https://community.cisco.com/t5/firewalls/replacing-primary-asa-in-h-a-pair/td-p/3369761 (2018)
Bottom line - you need only have the matching hardware and boot image (and any other files such as AnyConnect images) on the replacement unit. Give it a minimal failover config to match that on the failed unit and allow it to sync with the Secondary-Active. Then connect all the cabling and power it on. It should come up as Primary-Standby and synchronize running-config from the Secondary-Active unit. You may then (optionally) make it active with the command "failover active".
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: